Palo Alto Networks’ Unit 42 researchers identified three techniques, collectively named 'Pass-ta-key', that could allow malware on Windows computers to hijack passkeys stored in Google Password Manager.
The most severe attack targets the 32-byte Security Domain Secret, a master cryptographic key that could enable attackers to decrypt existing and future credentials without maintaining access to the victim's device.
While the research highlights vulnerabilities in synchronized passkey infrastructure, there is currently no evidence that these techniques have been exploited in real-world attacks or associated with known malware families.